CVE-2019-17621
Last modified
CVE-2019-17621 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.. CISA has confirmed active exploitation in the wild. EPSS estimates a 89.62% chance of exploitation in the next 30 days.
Description
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Dlink | Dir-859 Firmware | <= 1.05b03 | — |
| Dlink | Dir-859 Firmware | 1.06b01 | Beta1 |
| Dlink | Dir-822 Firmware | <= 2.03b01 | — |
| Dlink | Dir-822 Firmware | <= 3.12b04 | — |
| Dlink | Dir-823 Firmware | <= 1.00b06 | — |
| Dlink | Dir-823 Firmware | 1.00b06 | Beta |
| Dlink | Dir-865l Firmware | <= 1.07b01 | — |
| Dlink | Dir-868l Firmware | <= 1.12b04 | — |
| Dlink | Dir-868l Firmware | <= 2.05b02 | — |
| Dlink | Dir-869 Firmware | <= 1.03b02 | — |
| Dlink | Dir-869 Firmware | 1.03b02 | Beta02 |
| Dlink | Dir-880l Firmware | <= 1.08b04 | — |
| Dlink | Dir-890l Firmware | <= 1.11b01 | — |
| Dlink | Dir-890l Firmware | 1.11b01 | Beta01 |
| Dlink | Dir-890r Firmware | <= 1.11b01 | — |
| Dlink | Dir-890r Firmware | 1.11b01 | Beta01 |
| Dlink | Dir-885l Firmware | <= 1.12b05 | — |
| Dlink | Dir-885r Firmware | <= 1.12b05 | — |
| Dlink | Dir-895l Firmware | <= 1.12b10 | — |
| Dlink | Dir-895r Firmware | <= 1.12b10 | — |
| Dlink | Dir-818lx Firmware | All versions | — |
References
- https://packetstormsecurity.com/files/156054/D-Link-DIR-859-Unauthenticated-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://medium.com/%40s1kr10s/d-link-dir-859-rce-unautenticated-cve-2019-17621-en-d94b47a15104Exploit, Third Party Advisory
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10146Patch, Vendor Advisory
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10147Patch, Vendor Advisory
- https://www.dlink.com/en/security-bulletinVendor Advisory
- https://www.ftc.gov/system/files/documents/cases/dlink_proposed_order_and_judgment_7-2-19.pdfThird Party Advisory, US Government Resource
- https://packetstormsecurity.com/files/156054/D-Link-DIR-859-Unauthenticated-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://medium.com/%40s1kr10s/d-link-dir-859-rce-unautenticated-cve-2019-17621-en-d94b47a15104Exploit, Third Party Advisory
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10146Patch, Vendor Advisory
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10147Patch, Vendor Advisory
- https://www.dlink.com/en/security-bulletinVendor Advisory
- https://www.ftc.gov/system/files/documents/cases/dlink_proposed_order_and_judgment_7-2-19.pdfThird Party Advisory, US Government Resource
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-17621US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2019-17621?
How severe is CVE-2019-17621?
How do I fix CVE-2019-17621?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-1761A vulnerability in the Hot Standby Router Protocol (HSRP) su…4.3
- CVE-2019-17610HongCMS 3.0.0 has XSS via the install/index.php dbpassword p…6.1
- CVE-2019-17611HongCMS 3.0.0 has XSS via the install/index.php tableprefix …6.1
- CVE-2019-17612An issue was discovered in 74CMS v5.2.8. There is a SQL Inje…7.2
- CVE-2019-17613qibosoft 7 allows remote code execution because do/jf.php ma…9.8
- CVE-2019-1762A vulnerability in the Secure Storage feature of Cisco IOS a…4.4
- CVE-2019-17624"" In X.Org X Server 1.20.4, there is a stack-based buffer o…7.8
- CVE-2019-17625There is a stored XSS in Rambox 0.6.9 that can lead to code …9
- CVE-2019-17626ReportLab through 3.5.26 allows remote code execution becaus…9.8
- CVE-2019-17627The Yale Bluetooth Key application for mobile devices allows…6.5
- CVE-2019-17629CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin…4.8
- CVE-2019-1763A vulnerability in the web-based management interface of Ses…7.5
Are you affected by CVE-2019-17621?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
